07-28-2021 03:27 AM
I am trying to understand CoA, when I choose the type to be reauth, how would it be triggered?
From my understanding, the device (say an IP phone from a specific vendor) is authenticated for the first time, it wont be profiled yet, so ISE needs to re-auth the device a second time to profile it successfully and get it to hit on the correct authorization policy role based on it's type. But how does that happen? what do I need to do to trigger this reauth?
Solved! Go to Solution.
07-28-2021 05:52 AM
Hi @SMD28316 ,
CoA is the only communication that is initiated by the Authentication Server (ISE) to the Authenticator (NAD), it's critical for Profiling and Posture.
For a better understand of what triggers CoA, please take a look to the following table: Change of Authorization Issued for Each Type of CoA Configuration.
Hope this helps !!!
07-28-2021 05:52 AM
Hi @SMD28316 ,
CoA is the only communication that is initiated by the Authentication Server (ISE) to the Authenticator (NAD), it's critical for Profiling and Posture.
For a better understand of what triggers CoA, please take a look to the following table: Change of Authorization Issued for Each Type of CoA Configuration.
Hope this helps !!!
11-20-2024 08:57 AM
Scenarios |
No CoA Configuration |
Port Bounce Configuration |
Reauth Configuration |
Additional Information |
---|---|---|---|---|
Global CoA configuration in Cisco ISE (typical configuration) |
No CoA |
Port Bounce |
Reauthentication |
— |
An endpoint is disconnected on your network |
No CoA |
No CoA |
No CoA |
Change of authorization is determined by the RADIUS attribute Acct-Status -Type value Stop. |
Wired with multiple active sessions on the same switch port |
No CoA |
Reauthentication |
Reauthentication |
Reauthentication avoids disconnecting other sessions. |
Wireless endpoint |
No CoA |
Packet-of-Disconnect CoA (Terminate Session) |
Reauthentication |
Support to Wireless LAN Controller. |
Incomplete CoA data |
No CoA |
No CoA |
No CoA |
Due to missing RADIUS attributes. |
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide